Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE: 2019:2710-1 Moderate: Spectre-Meltdown-Checker Security Fix

opensuse
Calendar Grey December 31, 2019
Dist Opensuse Esm H88
A significant Fedora security enhancement addresses multiple flaws in the kernel that improves overall system protection.
An update that fixes two vulnerabilities is now available.

Description

This update for spectre-meltdown-checker fixes the following issues:

- feat: implement TAA detection (CVE-2019-11135 bsc#1139073)

- feat: implement MCEPSC / iTLB Multihit detection (CVE-2018-12207

bsc#1117665)

- feat: taa: add TSX_CTRL MSR detection in hardware info

- feat: fwdb: use both Intel GitHub repo and MCEdb to build our firmware

version database

- feat: use --live with --kernel/--config/--map to override file

detection in live mode

- enh: rework the vuln logic of MDS with --paranoid (fixes #307)

- enh: explain that Enhanced IBRS is better for performance than classic

IBRS

- enh: kernel: autodetect customized arch kernels from cmdline

- enh: kernel decompression: better tolerance against missing tools

- enh: mock: implement reading from /proc/cmdline

- fix: variant3a: Silvermont CPUs are not vulnerable to variant 3a

- fix: lockdown: detect Red Hat locked down kernels (impacts MSR...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2019-2710=1

Package List

- openSUSE Leap 15.1 (x86_64):

spectre-meltdown-checker-0.43-lp151.3.3.1

References

https://www.suse.com/security/cve/CVE-2018-12207.html

https://www.suse.com/security/cve/CVE-2019-11135.html

https://bugzilla.suse.com/1117665

https://bugzilla.suse.com/1139073

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:2710-1
Rating: moderate
Affected Products: openSUSE Leap 15.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here